Privacy notice · protocol v1

Evidence without silent profiling.

DealSeal stores only the evidence needed to run a ceremony, verify a receipt, or maintain a continuity page an X account has explicitly opted into.

Ceremony data

A room stores numeric X IDs, optional reference handles, the purpose and optional terms hash, wallet addresses, authenticated X event metadata, wallet signatures, expiry and the resulting receipt. The bot must briefly decrypt the exact ceremony message to compare it with the canonical tuple; it does not publish other X Chat content.

Public evidence

Anyone with a receipt ID can inspect that receipt. An opted-in continuity page is public by design and may show key fingerprints, published wallet bindings and receipt references. Do not put confidential deal terms in the purpose field; use a document hash when the terms themselves should remain private.

Consent and retention

Continuity monitoring is disabled by default. Revocation stops future key observations, but existing receipts and already committed daily roots remain immutable evidence. Operational logs should retain no bot PIN, OAuth token, wallet secret, decrypted non-ceremony messages, or participant private key.

Contact and deletion

Before commercial launch, the operator contact and jurisdiction-specific retention schedule must be added here. Requests cannot erase cryptographic facts already issued to counterparties or anchored publicly, but may remove uncommitted profile metadata where law permits.